- -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200212-9 - -------------------------------------------------------------------- DATE : 2002-12-22 13:12 UTC
- --------------------------------------------------------------------
From advisory:
"In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution.
These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage or files on a network filesystem or other untrusted source.
By carefully crafting such data an attacker might be able to execute arbitary commands on a vulnerable sytem using the victim's account and privileges.
The KDE Project is aware of several possible exploits of these vulnerabilities and is releasing this advisory with patches to correct the issues. The patches also provide better safe guards and check data f...Read the Full Advisory
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.